Appendix A Intrusion Detection System Architecture
System Components
A-38
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Major Data Structures
The various functional units communicate the following seven types of data:
•
Intrusion events—Produced by SensorApp. The sensor detects intrusion
events.
•
Error events—Caused by hardware or software malfunctions.
•
Status events—Reports of a change in the application’s status, for example,
that its configuration has been updated.
•
Control transaction log events—The sensor logs the result of a control
transaction.
•
Network access events—Actions for the NAC, for example, a block request.
•
Debug events—Highly detailed reports of a change in the application’s status
used for debugging.
•
Control transaction data—Data associated with control transactions, for
example, diagnostic data from an application, session logs, and configuration
data to or from an application.
All seven types of data are referred to collectively as IDS data. The six event
types—intrusion, error, status, control transaction log, network access, and
debug—have similar characteristics and are referred to collectively as IDS events.
IDS events are produced by the several different applications that make up the IDS
and are subscribed to by other IDS applications. IDS events have the following
characteristics:
•
They are spontaneously generated by the application instances configured to
do so. There is no request from another application instance to generate a
particular event.
•
They have no specific destination. They are stored and then retrieved by one
or more application instances.
Control transactions involve the following types of requests:
•
Request to update an application instance’s configuration data
•
Request for an application instance’s diagnostic data
•
Request to reset an application instance’s diagnostic data
•
Request to restart an application instance
•
Request for the NAC, such as a block request
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...